Authentication

Identity controls, described honestly.

GlacialBooks requires a verified email address on every account and reads that verification straight from the identity-provider session before any financial-account connection flow is offered. The control is enforced server-side so it holds even when a client is modified, and we describe what we run today rather than the policy we wish we ran.

Open account security

Account verification

Required before connecting financial accounts

Verified email address

Required

Financial account connections

Blocked until verified

Additional customer MFA

Coming soon

This panel describes the production control as it ships today. Financial connections require verified identity today. An additional customer factor will be shown here only after the control is available and enforced.

Verified email at signup

Every account must verify an email address before the application is usable. Verification is checked from the active identity-provider session on protected requests.

Plaid Link gate

GlacialBooks refuses to start or complete Plaid Link unless the active identity-provider session reports a verified email. The control is enforced independently of what is shown in the browser.

Critical systems

Production access to systems that store or process customer financial data requires centralized identity, scoped role assignment, and audit logging for security-relevant and accounting actions.

Support access

Internal support access is separate from customer organization roles, requires an approved internal identity, and records security-relevant activity for review.

Password and lockout controls

Password-reset links expire after 60 minutes and email-verification links expire after 24 hours. Local password accounts lock for 15 minutes after 5 failed sign-in attempts.

Additional customer MFA

Coming soon. The current financial-connection control requires a verified identity-provider email. This page will be updated when an additional customer factor is enforced.